SECURITYCRITICALCVE-2026-103110

CVE-2026-103110: Pexip Infinity Conferencing Node Critical RCE

A CVSS 9.8 unauthenticated RCE flaw in Pexip Infinity lets remote attackers execute code on Conferencing Nodes pre-38.2, 39.0, 39.1, and 40.0.

Dylan H.

Security Team

September 30, 2026
7 min read
CVE-2026-103110: Pexip Infinity Conferencing Node Critical RCE

Critical severity

Rated critical. Prioritise patching — see the remediation guidance below.

Affected Products

  • Pexip Infinity before 38.2 (38.1 and earlier)
  • Pexip Infinity 39.0
  • Pexip Infinity 39.1
  • Pexip Infinity 40.0

CVE-2026-103110: Pexip Infinity Conferencing Node Remote Code Execution

A critical remote code execution vulnerability tracked as CVE-2026-103110 has been disclosed in Pexip Infinity, a widely deployed enterprise and government video conferencing platform. The flaw carries a CVSS v3.1 score of 9.8 (Critical) and stems from improper input validation that lets a remote, unauthenticated attacker execute arbitrary code as an unprivileged user on a Pexip Infinity Conferencing Node — the component that terminates and mixes live call media.

The vulnerability was published September 30, 2026, via the National Vulnerability Database (NVD), with Pexip publishing corresponding guidance on its official security bulletins page. As of publication there is no public proof-of-concept exploit and the flaw is not listed in CISA's Known Exploited Vulnerabilities (KEV) catalog, but the combination of network exploitability, no authentication requirement, and no user interaction makes rapid weaponization plausible.


Vulnerability Overview

AttributeValue
CVE IDCVE-2026-103110
CVSS v3.1 Score9.8 (Critical)
CVSS VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Weakness ClassImproper Input Validation (several trackers also cite CWE-787, Out-of-Bounds Write)
Affected ComponentPexip Infinity Conferencing Node
Attack VectorNetwork
Authentication RequiredNone
User Interaction RequiredNone
Primary ImpactRemote Code Execution (unprivileged user context)
Public Exploit / PoCNone known at disclosure
CISA KEV ListedNo
SourceNVD / Pexip Security Bulletins

Technical Details

Root Cause

Pexip Infinity Conferencing Nodes process a large volume of attacker-reachable, network-facing input as part of real-time call signaling and media handling. NVD's published description frames the defect as improper input validation reachable by a remote party without any prior authentication; several third-party vulnerability trackers additionally classify the underlying weakness as CWE-787 (Out-of-Bounds Write), which would be consistent with memory corruption triggered by malformed input reaching an unchecked buffer or parsing routine. Pexip has not published full internal technical detail on the exact vector, which is standard practice for an unpatched or newly patched critical flaw to limit exploitation windows.

Because Conferencing Nodes are the media-plane workhorses of a Pexip Infinity deployment — they are explicitly designed to accept inbound call signaling and media from external endpoints — this is a pre-authentication, network-reachable attack surface by design, which is what drives the severity rating.

Exploitation Path

Attacker (network-reachable, no credentials)
  → Crafted call-signaling / media input sent to Pexip Conferencing Node
    → Malformed data processed without sufficient validation
      → Out-of-bounds condition / unsafe input handling triggered
        → Arbitrary code execution as an unprivileged user on the node
          → Potential pivot toward Management Node or internal network segments

CVSS Breakdown

The 9.8 score reflects:

  • Attack Vector: Network — exploitable without local or adjacent-network access
  • Attack Complexity: Low — no special conditions or race windows required
  • Privileges Required: None — pre-authentication exploitation
  • User Interaction: None — fully automatable
  • Confidentiality / Integrity / Availability Impact: High across all three axes

Code execution occurs as an unprivileged user rather than root, which somewhat limits (but does not eliminate) the blast radius of an initial compromise — privilege escalation and lateral movement would typically be required for full node takeover.


Impact Assessment

Impact AreaDescription
Code ExecutionArbitrary code execution on the Conferencing Node, initially as an unprivileged user
ConfidentialityExposure of in-progress call media, signaling metadata, and node configuration
IntegrityPotential tampering with conference sessions or node behavior
AvailabilityNode crash or disruption of active and future conferences hosted on the affected node
Lateral MovementA compromised Conferencing Node could serve as a foothold toward the Management Node or internal network
Sector ExposurePexip Infinity is widely used by government, healthcare, legal, and enterprise organizations for secure video conferencing — a compromise could expose sensitive, regulated communications

Affected Systems

Product / VersionStatus
Pexip Infinity before 38.2 (38.1 and earlier)Affected
Pexip Infinity 39.0Affected
Pexip Infinity 39.1Affected
Pexip Infinity 40.0Affected
Pexip Infinity 38.2 and later 38.x buildsNot affected (fixed)

Aggregated vulnerability-tracker data indicates Pexip has shipped fixed builds across every affected branch — reported as 38.2, 39.2, 40.1, and 41.0. Administrators should treat these as a starting point only and confirm the exact fixed build number for their deployed branch against Pexip's official bulletin before scheduling an upgrade.


Remediation

For Pexip Administrators

  1. Identify your deployed version — check the Management Node version against the affected list above (before 38.2, or 39.0/39.1/40.0).
  2. Upgrade immediately to the fixed build for your branch, prioritizing internet-facing or externally reachable Conferencing Nodes.
  3. Consult the official bulletin at docs.pexip.com/admin/security_bulletins.htm for the authoritative fixed-version matrix and any version-specific upgrade notes.
  4. Contact Pexip Support if an immediate upgrade is not feasible — Pexip's bulletin indicates mitigation options can be discussed directly with support for organizations that cannot patch right away.

For Security Teams

  1. Inventory all Pexip Infinity nodes (Management Node and every Conferencing Node) and confirm patch status fleet-wide — do not assume uniform versions across nodes.
  2. Restrict external exposure of Conferencing Nodes where possible, limiting inbound signaling/media traffic to expected endpoints and known IP ranges while patching is in progress.
  3. Monitor for anomalous behavior on Conferencing Nodes — unexpected process spawns, crashes, or resource spikes correlated with inbound call signaling.
  4. Review logs retroactively for malformed or unusual signaling/media traffic predating the patch, since no PoC being public today does not rule out quiet pre-disclosure probing.
  5. Segment the Pexip deployment from sensitive internal networks so a compromised Conferencing Node cannot directly reach high-value systems.

Defense-in-Depth

Priority 1: Patch to the fixed build for your branch (38.2 / 39.2 / 40.1 / 41.0 — confirm with Pexip)
Priority 2: Restrict/firewall external access to Conferencing Nodes to only what is operationally required
Priority 3: Network-segment Conferencing Nodes away from sensitive internal assets
Priority 4: Enable enhanced logging/monitoring on nodes during the patch window
Priority 5: Engage Pexip Support for interim mitigation if patching must be delayed

Key Takeaways

  1. CVE-2026-103110 is a CVSS 9.8 critical, pre-authentication remote code execution vulnerability in Pexip Infinity Conferencing Nodes.
  2. The flaw requires no authentication and no user interaction, and is remotely exploitable over the network — a textbook critical-severity profile.
  3. Affected versions: Pexip Infinity before 38.2, plus 39.0, 39.1, and 40.0; fixed builds are reported for every branch (38.2, 39.2, 40.1, 41.0) — verify exact numbers with Pexip.
  4. Code executes as an unprivileged user initially, meaning privilege escalation or lateral movement would typically follow a successful initial compromise.
  5. No public proof-of-concept and no CISA KEV listing exist as of disclosure, but organizations should not treat this as low urgency given the attack profile.
  6. Patch immediately, prioritizing internet-facing Conferencing Nodes, and contact Pexip Support for interim mitigation if an upgrade cannot happen right away.

Sources